{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:EBX7YPXOKVCHPPXJI6ZSUIVHI2","short_pith_number":"pith:EBX7YPXO","schema_version":"1.0","canonical_sha256":"206ffc3eee554477bee947b32a22a74695b2ce664675023656003767c788f51f","source":{"kind":"arxiv","id":"2605.19227","version":1},"attestation_state":"computed","paper":{"title":"Token by Token, Compromised: Backdoor Vulnerabilities in Unified Autoregressive Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Anna Rohrbach, Hossein Shakibania, Jonas Henry Grebe, Marcus Rohrbach, Tobias Braun","submitted_at":"2026-05-19T00:55:18Z","abstract_excerpt":"Unified autoregressive models (UAMs) are transformer models that generate text as well as image tokens within a single autoregressive pass. Shared parameters and a multimodal vocabulary simplify the training pipeline and facilitate flexible multimodal generation, yet might introduce new vulnerabilities. In particular, we are the first to show that this unified architecture enables multimodal backdoor attacks, where a trigger can propagate malicious effects across multiple output modalities. Specifically, we present the Token by Token Backdoor Attack (ToBAC), the first backdoor attack targeting"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.19227","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-19T00:55:18Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"21da0e6e52f6fb70077acdadcdb0f5b78da38ab4fe9a11553837ae93597a3a68","abstract_canon_sha256":"7885d2f3a4812c2be72cd485440b31a162c1482e8e5016e99bfcf6bd25dac870"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T01:05:34.477050Z","signature_b64":"FZCogM4owHz/gRdO4Ym5JSZ9owtUZ5qbzhM12HhpMboJ1DPTHwOzsoq9Q8RIIb78fb2QuZ9CyWYnTWtIrh9MBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"206ffc3eee554477bee947b32a22a74695b2ce664675023656003767c788f51f","last_reissued_at":"2026-05-20T01:05:34.476394Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T01:05:34.476394Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Token by Token, Compromised: Backdoor Vulnerabilities in Unified Autoregressive Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Anna Rohrbach, Hossein Shakibania, Jonas Henry Grebe, Marcus Rohrbach, Tobias Braun","submitted_at":"2026-05-19T00:55:18Z","abstract_excerpt":"Unified autoregressive models (UAMs) are transformer models that generate text as well as image tokens within a single autoregressive pass. Shared parameters and a multimodal vocabulary simplify the training pipeline and facilitate flexible multimodal generation, yet might introduce new vulnerabilities. In particular, we are the first to show that this unified architecture enables multimodal backdoor attacks, where a trigger can propagate malicious effects across multiple output modalities. Specifically, we present the Token by Token Backdoor Attack (ToBAC), the first backdoor attack targeting"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.19227","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.19227/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.19227","created_at":"2026-05-20T01:05:34.476490+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.19227v1","created_at":"2026-05-20T01:05:34.476490+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.19227","created_at":"2026-05-20T01:05:34.476490+00:00"},{"alias_kind":"pith_short_12","alias_value":"EBX7YPXOKVCH","created_at":"2026-05-20T01:05:34.476490+00:00"},{"alias_kind":"pith_short_16","alias_value":"EBX7YPXOKVCHPPXJ","created_at":"2026-05-20T01:05:34.476490+00:00"},{"alias_kind":"pith_short_8","alias_value":"EBX7YPXO","created_at":"2026-05-20T01:05:34.476490+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2","json":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2.json","graph_json":"https://pith.science/api/pith-number/EBX7YPXOKVCHPPXJI6ZSUIVHI2/graph.json","events_json":"https://pith.science/api/pith-number/EBX7YPXOKVCHPPXJI6ZSUIVHI2/events.json","paper":"https://pith.science/paper/EBX7YPXO"},"agent_actions":{"view_html":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2","download_json":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2.json","view_paper":"https://pith.science/paper/EBX7YPXO","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.19227&json=true","fetch_graph":"https://pith.science/api/pith-number/EBX7YPXOKVCHPPXJI6ZSUIVHI2/graph.json","fetch_events":"https://pith.science/api/pith-number/EBX7YPXOKVCHPPXJI6ZSUIVHI2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/action/storage_attestation","attest_author":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/action/author_attestation","sign_citation":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/action/citation_signature","submit_replication":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/action/replication_record"}},"created_at":"2026-05-20T01:05:34.476490+00:00","updated_at":"2026-05-20T01:05:34.476490+00:00"}